CISCO-UNIFIED-FIREWALL-MIB :: cufwAaicHttpNumTunneledConns

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-UNIFIED-FIREWALL-MIBcufwAaicHttpNumTunneledConns

cufwAaicHttpNumTunneledConns

Module: CISCO-UNIFIED-FIREWALL-MIB

OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumTunneledConns

OID (numeric): 1.3.6.1.4.1.9.9.491.1.5.2.1.3

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: The number of connections corresponding to HTTP protocol which were detected to be tunneling other application traffic streams. An instance of this would be InstantMessenger traffic running on HTTP.

For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of HTTP traffic payloads.

This value is accumulated from the last reboot of the firewall.

What is cufwAaicHttpNumTunneledConns?

This Counter64, in Connections, counts HTTP connections detected to be tunneling other application traffic streams, such as instant-messenger traffic running over HTTP, requiring HTTP-layer deep packet inspection, accumulated since the last reboot. An admin uses it to catch applications disguising their real traffic as ordinary web traffic to slip past port-based rules. A noticeable rise here on a network that officially bans IM tools would suggest users are tunneling that traffic through HTTP to evade the policy.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.5.2.1.3
snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumTunneledConns

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.5.2.1.3.1
snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumTunneledConns.1

Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumTunneledConns OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.491ciscoUnifiedFirewallMIBCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1ciscoUnifiedFirewallMIBObjectsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.5cuFwAaicGrpCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.5.2cufwAaicProtocolStatsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.5.2.1cufwAaicHttpProtocolStatsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.5.2.1.3cufwAaicHttpNumTunneledConnsCISCO-UNIFIED-FIREWALL-MIB